Live data from Hacker News

Reverse engineering Ticketmaster's rotating barcodes

conduition.io

1–10 of 737 posts

Re: Reverse engineering Ticketmaster's rotating barcodes

#3
post #2

Isn’t this a bit like irresponsible disclosure? Since this may be considered a security vulnerability. Although it’s all client side, I’m sure there’s some basis for a lawsuit here.

It is my opinion that you do not need to responsibly disclose "security by obscurity"

Additionally, what is irresponsible here? Its not like this gives you the capability to clone tickets without first having a ticket in the first place.

Re: Reverse engineering Ticketmaster's rotating barcodes

#4
post #2

Isn’t this a bit like irresponsible disclosure? Since this may be considered a security vulnerability. Although it’s all client side, I’m sure there’s some basis for a lawsuit here.

How is this a security vulnerability? It's displaying the exact bits Ticketmaster uses and explaining what those bits are. They're not circumventing security systems, just the requirement to use the app.

Re: Reverse engineering Ticketmaster's rotating barcodes

#5
post #2

Isn’t this a bit like irresponsible disclosure? Since this may be considered a security vulnerability. Although it’s all client side, I’m sure there’s some basis for a lawsuit here.

The app-based barcodes don’t seem to be solving a security problem for customers - they seem to be for the purpose of ensuring that traditional scalping doesn’t work, forcing ticket resale into a market that TicketMaster can profit from.

I would consider it unethical to publish details of an unpatched vulnerability that allowed ticket forgery, but I don’t think it’s unethical to bypass DRM-like controls for personal convenience rather than commercial purposes.

Of course opinions may differ on this.

Re: Reverse engineering Ticketmaster's rotating barcodes

#6
post #2

Isn’t this a bit like irresponsible disclosure? Since this may be considered a security vulnerability. Although it’s all client side, I’m sure there’s some basis for a lawsuit here.

Responsible disclosure is something you pay for, not something you are entitled to.

Re: Reverse engineering Ticketmaster's rotating barcodes

#7
post #2

Isn’t this a bit like irresponsible disclosure? Since this may be considered a security vulnerability. Although it’s all client side, I’m sure there’s some basis for a lawsuit here.

It requires sniffing your own session credentials first, which I don't see as a security vulnerability.

The only thing it allows you to do is sell your ticket, which is legal to do.

Re: Reverse engineering Ticketmaster's rotating barcodes

#9
post #2

Isn’t this a bit like irresponsible disclosure? Since this may be considered a security vulnerability. Although it’s all client side, I’m sure there’s some basis for a lawsuit here.

"Responsible disclosure" is poorly defined corporate wishcasting, and certainly not any sort of best practice or legal shield.

Re: Reverse engineering Ticketmaster's rotating barcodes

#10
> There’s no risk that your ticket won’t get you in

Isn’t this not true? The risk with printable tickets is that a seller could sell it to multiple people, who all print it out, but then only the first person who uses it can get in?

Even if the venue doesn’t check to see if a ticket has already been used, only one person can sit in the actual seat.

Post reply on HN